Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

81–90 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#81
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…

Google, Mozilla, et al. should make a commitment to revoke the trust of any CA that is found to partake in behavior like that. Even retroactive revocation of existing certificates shouldn't be off the table if the offense is egregious enough.

It's actually pretty scary seeing just how many CAs are in the list of trusted CAs on any given device. While no government is beyond reproach, I do wish there were a way for me as a user to say "don't trust anything signed by CAs outside of these few countries, since it's most likely a hijack, phishing, or in the rare case that I did try to visit some random site, I can approve it manually."

Re: New German law would force ISPs to allow secret service to install trojans

#82
post #69

Earlier quoted context omitted.

And Tor.

https://metrics.torproject.org/rs.html#search/country:de This shows 1,648 relays potentially having their traffic monitored under this law. Out of 6,432 relays, that makes up more than 25% of all Tor relays. Unfortunately, Tor's design doesn't really go far enough in protecting against adversaries with large swaths of visibility. Perhaps it's time for people to begin shifting to I2P, or some other overlay network wit…

Tor might not protect anonymity effectively in that case, but in the case given it would still offer protection because of the way the relay circuits are designed.

Re: New German law would force ISPs to allow secret service to install trojans

#83

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

>Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. Because they're not necessarily contradictory. This doesn't just give secret services a blank cheque to spy on everyone, it just provides intelligence agencies with a tool. I'm German and I don't object in principle to the fact that intelligence, under supervision of the govern…

The scary stuff about the current development is, that we get flooded with arguments about hardcore criminals, but if you look at the actual changes to the laws, such restrictions are not made, instead these extreme measures are allowed for petty reasons and some politicians will still keep pushing for even more totalitarianism. These siloviki want mass surveillance comparable to what Chinas Ministry of State Security or USAs National Security Agency have. It does not matter if Germany is not ruled by an autocratic regime at the moment, once such systems are in place, it will be.

Re: New German law would force ISPs to allow secret service to install trojans

#84
post #78
post #14

Earlier quoted context omitted.

TIL. Didn’t know Germany was involved in that.

It's funny as the Germans had different priorities from the US. The US mainly wanted to use it to extract information, while the Germans also wanted to increase profits so that they have funds outside of parliamentary control and supervision. So they looked more at the business side of things.

I guess funding was not a big issue for the CIA...

Re: New German law would force ISPs to allow secret service to install trojans

#85

Earlier quoted context omitted.

They can wiretap, sure, but they can’t practically compel you to give up your book cipher.

Sure, but a police operation surely could attempt to swap the book cipher out for a compromised one, no? I think the idea that communication ought to be categorically out of reach of intelligence is very novel. I don't think it was even conceivable decades ago that, with legal justification, intelligence could not hack or be completely locked out of the communication of some network. For criminals who are savy enough…

Legal checks are a mile-long leash, no matter how strong the cord. This is exchanging freedom for security, since a backdoor like this doesn’t require breaking glass.

Re: New German law would force ISPs to allow secret service to install trojans

#86

Is it possible to modify HTTPS traffic? Wouldn't they have to replace the CA certs on the target machine first before being able to modify that traffic?

I think your worry is a bit out of scope. There is a thing called "Verhaeltnismaessigkeit" in Germany, and in most other countries where "The Rule Of Law" applies, to paraphrase Trudeau. Meaning: You are not allowed to burn down the house just because the neighbor was playing the music too loudly. So others are not to caught in the cross-fire of this operation. So it will be a very technical challenge to overcome these obstacles. And since an ISP is not providing updates, coercing OS vendors to alter the CA's for a specific user is a bit far-fetched. The more likely approach is the acquisition of cryptographic keys to create one's own SSL-Certificiate. Now: This is the domain of the intelligence-community. Their bread and butter. Compared to the rest of the world, this community is heavily regulated; you just have to think of the CIA's Black Budget or other agencies from less pleasent countries to get a comparison. It is best they get the legal framework in place (s.o. heralded it as the OS for society once). The alternative would be clandestine operations outside the law, and that is never good. Only requirement I would demand for s.th. like this: The solution mustn't be scalable, as to ensure to avoid a subjecting large swats of a population to this, which is challenging with technologies these days. The good thing is that ISPs will not keel over just because the police are requesting it. After all they have a reputation and their customers to protect and, let's face it, this is not China, Russia, Iran or some other country were you vanish for far less than demanding more paperwork and speaking out against executive orders. As long as the mechanisms of a society are functioning and everyone watches everyone and there is due process it works. It will be a problem if these mechanisms fail though. I for one will be watching with keen interest.

As for the new root certificate to a domain for the agencies: I already pointed out, s.w. in this discussion, that there is a mechanism called Certificate Pinning. Works wonders if the server configured it. So yes, they are working on the legal framework, but thanks to the foresight of engineers and people concerned with safety for the general non-technical and technical internet-population, it is a hard challenge officials are facing.

Re: New German law would force ISPs to allow secret service to install trojans

#88
post #84
post #78

Earlier quoted context omitted.

It's funny as the Germans had different priorities from the US. The US mainly wanted to use it to extract information, while the Germans also wanted to increase profits so that they have funds outside of parliamentary control and supervision. So they looked more at the business side of things.

I guess funding was not a big issue for the CIA...

They are still flush with cash from decades of running cocaine.

Re: New German law would force ISPs to allow secret service to install trojans

#89
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

think mobile - isp are the place to conduct baseband attacks from.

Re: New German law would force ISPs to allow secret service to install trojans

#90
post #82
post #69

Earlier quoted context omitted.

https://metrics.torproject.org/rs.html#search/country:de This shows 1,648 relays potentially having their traffic monitored under this law. Out of 6,432 relays, that makes up more than 25% of all Tor relays. Unfortunately, Tor's design doesn't really go far enough in protecting against adversaries with large swaths of visibility. Perhaps it's time for people to begin shifting to I2P, or some other overlay network wit…

Tor might not protect anonymity effectively in that case, but in the case given it would still offer protection because of the way the relay circuits are designed.

Unless it's an exit node. 251 of 1,249 exit nodes reside in Germany, or roughly 20%. Exit nodes aren't supposed to modify traffic, so if the compromise is happening upon leaving the exit node en route to whatever destination, that would still trickle back through all the hops.
Post reply on HN